FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kwcheng__FTNT
Article Id 346334
Description This article describes that deleting the default local certificate of the FortiGate is not possible.
Scope All FortiOS platform
Solution

All FortiOS comes with its respective default self-signed local certificates. These default certificates are as follows:

 

Fortinet_CA_SSL
Fortinet_CA_Untrusted
Fortinet_Factory
Fortinet_Factory_Backup
Fortinet_GUI_Server
Fortinet_SSL
Fortinet_SSL_DSA1024
Fortinet_SSL_DSA2048
Fortinet_SSL_ECDSA256
Fortinet_SSL_ECDSA384
Fortinet_SSL_ECDSA521
Fortinet_SSL_ED448
Fortinet_SSL_ED25519
Fortinet_SSL_RSA1024
Fortinet_SSL_RSA2048
Fortinet_SSL_RSA4096
Fortinet_Wifi

 

These default certificates cannot be deleted or removed even if it is not being used. The following error will prompt if the administrator tries to delete them via CLI:

 

Tiara-kvm05 (local) # delete Fortinet_Wifi
Can not delete a static table entry
Command fail. Return code -61

 

This is an expected behavior and should not be a concern. Just replacing the certificate under its respective configuration with the new imported local certificate is sufficient if replacing the default self-signed local certificate is required.